Remote Code Execution in OSSRS SRS Simple Realtime Server by Unauthorized RTMP Access
CVE-2026-68004
9.8CRITICAL
What is CVE-2026-68004?
An identified flaw in OSSRS SRS (Simple Realtime Server) versions prior to 5.0.213 can lead to a potential exploitation scenario where attackers are able to execute arbitrary code. This vulnerability is linked to improper RTMP publish authorization and system configuration settings that control vhost-level security. The specific implementation in the SRS RTMP listener components, notably within the SrsSecurity::check() method, exposes the server to risks through unsuspecting access points. It is crucial for users to upgrade their installations and review configurations to mitigate potential threats.
